Exfiltrating data from remote browser localStorage using XSS (Insomnihack teaser 2017 web 200 writeup)
Exploiting internal tomcat server (with default credentials) using SSRF (Insomnihack teaser 2017 Web 50 writeup)
Practical Web Defense is a unique course which focus on both attacking and *defending* web Applications unlike the traditional courses which focuses only on attacking applications.
How can we bypass CSP using whitelisted CDNs and path traversal (SECT CTF 2016 web 400 writeup)
Using the legacy windows 8.3 filename short code, we bypass the filter to download files. (MMACTF 2016 web 150 writeup)